Skip to content
NiteTale
How it worksFor parentsPricing
EN·PL

NiteTale

Privacy Policy

Last updated: 8 September 2026

On this page

  1. 1. Who we are
  2. 2. Scope
  3. 3. What we collect, why, and how long we keep it
  4. 4. Story generation and AI providers
  5. 5. Children
  6. 6. Legal bases
  7. 7. Who we share data with
  8. 8. International transfers
  9. 9. Retention
  10. 10. Security
  11. 11. Your rights
  12. 12. How to delete your account and data
  13. 13. Device permissions and local data
  14. 14. Website
  15. 15. Changes to this Policy
  16. 16. Contact
← Back to NiteTale

Effective date: 8 September 2026

This Privacy Policy explains how we process personal data when you use the NiteTale mobile application (the "App") and the website https://nitetale.app. It should be read together with our Terms of Use.

We have tried to keep this document short and plain. If anything is unclear, write to us at [email protected].

1. Who we are

NiteTale is run by two sole traders who act as joint controllers of your personal data (Article 26 GDPR) ("we", "us", "our"):

SOFTWARE Paweł Śląski — publisher of the Android app on Google Play
ul. Ignacego Matuszewskiego 15A/2, 80-288 Gdańsk
NIP 7422172307, REGON 366588343

szygiTech - Usługi IT Mateusz Szygenda — publisher of the iOS app on the App Store
ul. 3 Maja 13/7, 81-728 Sopot
NIP 5851461436, REGON 365588849

How we split the work. SOFTWARE Paweł Śląski publishes the Android app and handles everything tied to Google Play (the listing, billing records, store support). szygiTech - Usługi IT Mateusz Szygenda publishes the iOS app and handles everything tied to the App Store. The story service behind both apps, its servers and the data described in this Policy are run by both of us together, and we decide jointly what is collected and why. We have a written arrangement between us that sets this out; its essence is this section, and you can ask for a summary at any time.

One contact point. For anything about your data, write to [email protected]. You may exercise your rights against either of us, whichever app you use; we forward requests to each other and answer as one.

2. Scope

This Policy covers:

  • the NiteTale App, distributed through the Apple App Store and Google Play;
  • our servers that generate and deliver stories;
  • the website https://nitetale.app.

It does not cover services operated by others that you use alongside NiteTale, such as your Google or Apple account, Google Play or the App Store. Those are governed by their own privacy policies.

3. What we collect, why, and how long we keep it

Account data

  • What: email address (a private relay address if you hide your email with Sign in with Apple), display name where the sign-in provider shares one, Firebase user identifier, sign-in provider (Google or Apple), last sign-in time, account created and updated timestamps.
  • Why: to create and secure your account, to identify you across devices, and to contact you about the Service.
  • Legal basis: performance of a contract.
  • How long: for as long as your account exists, then deleted within 30 days of a deletion request (see section 12).

Wishes and story generation records

  • What: the wish text you type (up to 2,000 characters), the chosen story language, timestamps, job status, error code and message if generation failed, the generated story text, the storage path of the generated audio file, and technical request identifiers used for tracing.
  • Why: to generate your story, to show its status in the App, to diagnose failures, to prevent abuse, and to count stories against your monthly allowance.
  • Legal basis: performance of a contract; legitimate interests (security, abuse prevention, service improvement).
  • How long: up to 90 days after the story is completed, unless we need a record longer to investigate abuse or to handle a legal claim.

Generated audio files

  • What: the narrated audio of your story.
  • Why: to let you download the story to your device.
  • Legal basis: performance of a contract.
  • How long: about 24 hours after the story is ready, after which the file is removed from our servers. The copy saved on your device remains until you delete it or uninstall the App.

Usage counters

  • What: the number of stories generated in the current monthly period.
  • Why: to enforce the limits of your plan.
  • Legal basis: performance of a contract.
  • How long: for as long as your account exists.

Subscription and entitlement data

  • What: Google Play purchase token, an app user identifier, entitlement identifier, product identifier, store, environment (production or test), purchase and expiry dates.
  • Why: to activate and manage NiteTale Premium and to meet accounting obligations.
  • Legal basis: performance of a contract; legal obligation (tax and accounting).
  • How long: for the statutory retention period, which in Poland is 5 years for accounting records.

App analytics

  • What: app usage events (for example screen views, a story being requested or played), a Firebase app-instance identifier, device model and operating system version, app version, language, and approximate region derived from your IP address, as collected by Firebase Analytics under Google's policies. We do not collect the advertising ID, precise location or crash logs, and we do not use analytics for advertising.
  • Why: to understand how the App is used and to improve it.
  • Legal basis: legitimate interests; consent where the platform or law requires it.
  • How long: up to 14 months, per our Google Analytics retention settings.

Support correspondence

  • What: your email address and the content of messages you send us.
  • Why: to answer your questions and handle requests.
  • Legal basis: legitimate interests; legal obligation where a request concerns your rights.
  • How long: for as long as needed to resolve the matter and to document that we did so.

We do not sell personal data. The App contains no advertising and no third-party advertising SDKs.

4. Story generation and AI providers

When you submit a wish, our servers send the wish text and the chosen language to Google's Gemini models to write the story, and then send the story text to Gemini's text-to-speech to narrate it. At present Google is the only AI provider we use; if that changes, we will update this Policy and the list in section 7.

If you include your child's name or other personal details in a wish, they form part of the text sent to Google. We process them only to generate that story, on your instruction, and we do not use wishes or stories to train AI models. Google acts as our processor under the Gemini API terms, which restrict its use of the data. Details are in section 7.

If you report a story to us as harmful or unsuitable (see the Terms of Use), we look at the wish, the story text and the audio to handle the report, and keep a record of the report and what we did about it for up to 12 months.

5. Children

NiteTale is directed at adults, namely parents and guardians. Children are the listeners of stories, not users of the Service. We do not knowingly create accounts for, or collect personal data directly from, children under 16 in the European Union or under 13 in the United States.

If a parent chooses to include a child's name or other details in a wish, the parent decides what to share and we process it solely to generate that story. If you believe a child has provided us with personal data directly, please contact us at [email protected] and we will delete it.

6. Legal bases

Under the General Data Protection Regulation (GDPR), we rely on the following bases:

  • Performance of a contract (Article 6(1)(b)): your account, story generation, and purchases.
  • Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing abuse, analysing usage, and improving the Service. We balance these interests against your rights and you can object at any time (see section 11).
  • Consent (Article 6(1)(a)): where required, for example for optional analytics on platforms that ask for it. You can withdraw consent at any time.
  • Legal obligation (Article 6(1)(c)): keeping tax and accounting records.

7. Who we share data with

We use the following processors to run the Service. Each receives only the data needed for its purpose.

  • Google LLC / Google Ireland Limited: Firebase Authentication (sign-in with Google or Apple), Firebase Analytics (app usage analytics), Google Play Billing (purchases), and the Google Gemini API (story text generation and text-to-speech). Your wish text and the generated story are sent to Google to produce the story and its narration.
  • Apple Inc. (iOS app): Sign in with Apple, if you choose it, sends us the identifier and email address Apple provides, which may be a private relay address; App Store In-App Purchase handles subscriptions bought on iOS, and we receive the purchase receipt through RevenueCat.
  • Cloudflare, Inc.: object storage (R2) for generated audio files.
  • RevenueCat, Inc.: subscription management. Receives the Google Play purchase token or the App Store receipt and an app user identifier, and sends us entitlement events (entitlement id, product id, store, environment, purchase and expiry dates).
  • Our hosting providers within the EU/EEA or under appropriate safeguards, which run our servers and database.

We may also disclose data where the law requires it, to protect the rights and safety of our users, or in connection with a merger or sale of our business, in which case this Policy will continue to apply to your data.

8. International transfers

Some of our providers are located in the United States. Where personal data is transferred outside the EU/EEA, we rely on the EU–US Data Privacy Framework for providers certified under it, and otherwise on the European Commission's Standard Contractual Clauses together with additional safeguards where appropriate. You can ask us for more information about these safeguards at [email protected].

9. Retention

In summary, we keep:

  • account data for as long as your account exists;
  • wish texts and story generation records for up to 90 days after completion, unless needed longer for abuse investigation or legal claims;
  • generated audio on our servers for about 24 hours after the story is ready;
  • billing and entitlement records for the statutory retention period (5 years in Poland);
  • analytics data for up to 14 months.

When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you.

10. Security

We protect personal data with technical and organisational measures, including encryption in transit (TLS), access controls and least-privilege permissions for our staff and systems, and short-lived pre-signed download links (valid for 15 minutes) for audio files. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we work to protect your data and will notify you and the relevant authority of a breach where the law requires it.

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict processing in certain circumstances;
  • receive your data in a portable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing that took place before withdrawal;
  • lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO, ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl). You may also complain to the authority in the country where you live or work.

To exercise any of these rights, email [email protected] from the address linked to your account. We will respond within one month; this may be extended by two further months for complex requests, in which case we will tell you.

12. How to delete your account and data

You can request deletion of your NiteTale account and the personal data associated with it at any time. The same steps are on a dedicated page: Delete your account.

  1. Send an email to [email protected] from the email address linked to your NiteTale account, with the subject "Delete my account".
  2. We will confirm the request and delete your account and associated server-side data, including account data, wish texts, generation records, and usage counters, within 30 days.
  3. We keep only the data we are legally required to retain, such as billing records needed for tax and accounting purposes, for the statutory period.
  4. Deleting your account does not cancel a subscription bought in Google Play or the App Store. Cancel it in the store before or after requesting deletion to avoid further charges.
  5. Stories and audio saved on your device are not stored on our servers. Remove them by uninstalling the App or by clearing the App's data in your device settings.

If you cannot access the email address linked to your account, contact us anyway and we will verify your identity by other means.

13. Device permissions and local data

The App requests the following Android permissions:

  • Internet and network state: to communicate with our servers.
  • Foreground service (media playback): to keep playing a story when the App is in the background.
  • Notifications: to show playback controls and to tell you when a story is ready.

The App does not request access to your microphone, camera, contacts, or location.

On your device the App stores downloaded audio, story text, library metadata (in a local database), your preferences, and an API key or session token used to talk to our servers. The App derives a stable profile identifier from your account to keep this data separate per account. Depending on your device settings, Android's automatic backup may include the App's data in your Google account backup; you control this in your device's backup settings.

14. Website

The website https://nitetale.app serves static pages only. It does not use cookies, does not run analytics, and does not load third-party scripts. Fonts are self-hosted. The language switch on the website does not store anything on your device. When you visit the website, our hosting provider may record standard server logs (such as IP address and requested page) for security and operational purposes for a short period.

15. Changes to this Policy

We may update this Policy from time to time. The effective date is shown at the top of this page. If we make material changes, we will let you know in the App or on our website at least 14 days before they take effect. We encourage you to review this Policy periodically.

16. Contact

SOFTWARE Paweł Śląski — publisher of the Android app on Google Play
ul. Ignacego Matuszewskiego 15A/2, 80-288 Gdańsk
NIP 7422172307, REGON 366588343

szygiTech - Usługi IT Mateusz Szygenda — publisher of the iOS app on the App Store
ul. 3 Maja 13/7, 81-728 Sopot
NIP 5851461436, REGON 365588849

Email: [email protected] Website: https://nitetale.app


NiteTale
Terms of UsePrivacy PolicyDelete account[email protected]Polski

© 2026 NiteTale. Made quietly in Poland. All rights reserved.

v1.0